Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Phase 7 publication editionPOL-SECURITY

Information security

Control access, information, change and support operations.

Full public textOrganization/contract scoped

This is the full text published in the Phase 7 package. Effective dates, responsible contacts and contract-specific parameters are maintained in the corresponding release and deployment records.

01

Control scope and accountability

The system owner identifies assets, trust boundaries and accountable roles. Proposed controls are mapped to actual configurations; publishing a description does not establish implementation. Mobile-ID's ISMS scope is referenced separately and does not certify every component automatically.

02

Accounts and authorization

Administrative accounts identify individuals, are task-scoped and approved before use. Apply least privilege, separation of sensitive duties and additional authentication under the risk profile. Role changes and departures trigger revocation, entitlement updates and checks of open sessions. Shared-account exceptions require approval and accountability.

03

Keys, certificates and secrets

Secrets do not belong in source code, websites, samples or logs. Manage issuance, storage, rotation and revocation by component; separate key administration from data access where the architecture requires it. Track device certificates, expiry and compromise without disabling TLS validation as a connectivity workaround.

04

Environments and transport

Production, UAT and development have separate permissions, data and configuration. Production raw biometrics are not a default testing dataset. Protected transport, mTLS where applicable and network policy follow the approved connectivity profile. An isolated environment must not be described as directly calling external services.

05

Data protection and access

Separate the biometric vault, business records and evidence according to approved boundaries. Do not search across organizations by default. Describe encryption by actual location and processing state; do not claim encrypted matching unless the engine supports it. Exports need a purpose, approver and audit trail.

06

Development and change management

Changes to code, firmware, algorithms, thresholds and policy require impact assessment, testing and risk-based approval. Versions document dependencies, provenance and rollback. Security, dependency and vulnerability checks follow approved procedures; results are tied to the actual version rather than reused unconditionally.

07

Logging, monitoring and support

Logs retain minimal event references, not secrets, tokens or biometric images. Support access is customer-authorized, scoped and time-bound, with operator, reason and outcome recorded. Alerts and anomalies enter incident handling; an alert alone does not replace an authorized business decision.

08

Exceptions, backups and review

Security exceptions require asset-owner approval, risk assessment, compensating controls and a review point. Backup/restoration tests include prior revocations and deletions. Project closure revokes accounts and secrets, disposes of temporary data and records handover and remaining limitations.

Responsibility & deployment annex

Detailed responsibilities are determined by activity and deployment records; this public document does not replace customer-specific contractual annexes.

  • The relying organization defines business purposes, populations and operational authority within the deployment.
  • Mobile-ID supplies and operates components within the agreed scope, including integration, control configuration and related evidence.
  • Device suppliers support models, firmware, SDKs and maintenance within authorization; data access is never implicit.
  • Legal, security and service ownership assignments are maintained in each organization’s operating records.

Execution and evidence cycle

  1. Record purpose, organization, data/device scope and the business reference.
  2. Verify authority, applicable conditions, configuration and relevant obligations.
  3. Execute with data minimization, authorization and necessary evidence.
  4. Close with confirmations from relevant systems, response handling and remaining exceptions.

Legal and reference sources

Detailed obligations, periods and exceptions apply according to law, contract and the actual service configuration.

Contact about applicability

Send contact details and a general question only; sensitive records require a confirmed channel.

info@mobile-id.vn

Search Trusted Palm ID

Selected interface